Invalid resource configuration error while creating AWS IoT Certificate using serverless framework

Viewed 211

I am trying to create an AWS IoT Thing using Serverless Framework. Following is my YAML file for the same.

I am getting "Error occurred during operation 'Invalid certificate resource configuration'..".

Any clue what the issue can be?


service: winds-delivery-infra

provider:
  name: aws
  runtime: nodejs12.x
  stage: dev
  region: ap-south-1

functions:
  hello:
    handler: handler.hello

resources:
  Resources:
    IoTThing:
      Type: AWS::IoT::Thing
    IoTPolicy:
      Type: AWS::IoT::Policy
      Properties: 
        PolicyDocument:
          Version: "2012-10-17"
          Statement:
            - Effect: Allow
              Action: ["iot:Connect"]
              Resource: "*"
            - Effect: "Allow"
              Action: ["iot:Publish","iot:Subscribe","iot:Receive"]
              Resource: "*"
    IoTCertificate:
      Type: AWS::IoT::Certificate
      Properties:
        Status: "ACTIVE"
    PolicyPrincipalAttachmentCert:
      Type: AWS::IoT::PolicyPrincipalAttachment
      Properties:
        PolicyName:
          Ref: IoTPolicy
        Principal: { Fn::GetAtt: [IoTCertificate, Arn] }
1 Answers

If you would like AWS CloudFormation to issue an IoT certificate for you, you need to tell it your own CSR (Certificate Signing Request). You can, for example, use openssl to generate a CSR for you:

openssl req -newkey rsa:2048 -keyout PRIVATEKEY.key -out MYCSR.csr

Once you have your CSR, you can then update your CloudFormation with it as below, and it will work:

    IoTCertificate:
      Type: AWS::IoT::Certificate
      Properties:
        Status: "ACTIVE"
        CertificateSigningRequest: "-----BEGIN CERTIFICATE REQUEST-----\nMIIE0DCCArgCAQAwg......uOQIKNqgCxzmqy\n-----END CERTIFICATE REQUEST-----\n"
Related